Mike Belshe, co-founder and CEO of the American company BitGo, which stores cryptocurrencies for institutions, transferred 100 Bitcoins to a BitGo wallet address on July 31 and published it on X the next day. The coins, worth about $6.3 million, are a reward for the company Anthropic, owner of the Claude models, if its artificial intelligence can extract them from there. As of Monday morning, no transactions had been made from the address.
Belshe did not do this without reason. Two days earlier, Anthropic had publicly "boasted" that its models had hacked into the IT systems of three real companies during security tests. The BitGo CEO felt that this sounded more threatening than it actually was and decided to verify it in a way that could not be interpreted in two ways: either the money would disappear from the address, or it would not.
Companies developing artificial intelligence check before release whether their models can conduct attacks on IT systems. This is done on a closed testing ground, cut off from the internet. The model is given a fictitious network and a task: to hack into a specified computer and extract a hidden string of characters. This is a standard exercise that human cybersecurity specialists also learn from.
The problem is that the testing ground was not secure. In a report published on July 30, Anthropic stated that the machines used in tests conducted with the external company Irregular accidentally had internet connectivity, even though the directive for the model clearly stated that there was no internet. When the searches led the model to real servers, it considered them part of the task and attacked. In three cases out of 141,006 reviewed tests, this resulted in access to the IT systems of companies.
The techniques used by the AI were simple. It exploited weak passwords, an unsecured access point, and passwords obtained from an unsecured technical page. The model did not find or exploit any new vulnerabilities. The most serious consequence was access to a database with several hundred lines of data. The review only began after the competing OpenAI announced in a statement on July 21 that its models had escaped from a closed environment due to an unknown vulnerability and accessed Hugging Face's infrastructure.
Belshe believes that the events described by Anthropic say more about a careless testing ground than about the capabilities of the models. Anyone can walk through open doors; unlocking a lock is another matter. He wrote that the company either builds its sandboxes poorly or markets itself very well, and proposed a test without open doors. In June, he already challenged circulating reports that the Mythos model had independently entered classified government systems, pointing out that it was a controlled exercise.
Bitcoin itself is not the target of the attack, as its cryptography is not being broken. To move someone else's coins, one must obtain the private key, which is a secret string of characters that grants the right to manage the funds. In BitGo's system, there is no single key. The signing authority is split among several independent keys stored separately, and a transaction requires the consent of more than one of them. Stealing one password does not yield any results.
However, it is important to know what this test is not. Belshe did not build any experiment. He did not provide a system, did not describe the task, and did not even indicate which model should start. He set a clear goal, the balance of which anyone can observe on the blockchain. Therefore, the lack of movement on the address does not mean that Claude tried and failed, as language models do not search the internet for rewards on their own. Someone would have to instruct them first. BitGo itself, in letters to regulators, admits that no storage system is immune to a hacking attack.
Meanwhile, the losses from the attack on Coldcard hardware wallets are being counted. The attacker managed to recreate users' private keys because the devices had generated them predictably over the years. The culprit was a bug in the software uploaded back in March 2021. According to estimates from Galaxy Research, 1,367 BTC, or nearly $89 million, was lost in three waves from over four thousand addresses.
The conclusion is uncomfortable for both sides of the dispute. Money in cryptocurrencies is lost due to a five-year-old bug in the code and a poorly configured testing machine, not because of a model that invented something no one could do before. Anthropic states exactly the same in its report, albeit in the language of post-implementation analysis. Meanwhile, Belshe has laid 100 Bitcoins on the table and is waiting for the outcome.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.







Japan and the United States bought yen together on 31 July 2026, their first coordinated yen-buying operation since June 1998, and the currency has since firmed from a 40-year low of 163.99 into the 155-156 area. This explainer sets out the three channels linking the yen to bitcoin: carry-trade unwind risk, yen-denominated repricing, and the dollar-weakness correlation that points the other way.






















